Fake ‘Claude’ App Spreads RevStealer Malware Targeting Crypto
A counterfeit ‘Claude Opus 5 Free Desktop’ app is distributing RevStealer, Windows malware that steals browser credentials, messaging data and files from over 50 crypto wallets.
Morphisec, a cybersecurity company, reported on Monday that a fake “Claude Opus 5 Free Desktop” application is being used to distribute RevStealer, a Windows malware strain that exfiltrates browser passwords, cookies, messaging data and selected documents.
The researchers found RevStealer inspects local browser databases and password-manager records, collects cookies and VPN or remote-access configuration files, captures messaging data and takes screenshots. The malware is also programmed to copy specific documents and files that may contain private keys or wallet backups.
RevStealer targets more than 50 types of cryptocurrency wallet files stored on infected machines. The malware searches common wallet locations and backup files, increasing the risk to users who keep private keys, seed phrases or wallet backups on the same device used for web browsing or messaging.
The infection routine includes multiple anti-analysis and environment checks. RevStealer evaluates available memory, number of processor cores, hostname, username and graphics hardware, and it monitors timing delays typical of debugging and sandbox environments. If the system does not appear to be a normal end-user device, the malware stops. If checks pass, the payload is decrypted, saved under a randomized filename and executed with minimal visible activity.
Morphisec’s report notes the malware is designed to leave few traces on the infected machine, which can complicate detection and forensic analysis. The researchers identified earlier distribution through GitHub repositories and game-cheat sites but flagged the counterfeit Claude app as a prominent recent delivery method that uses social-engineering to lure users with free access claims.
Kaspersky, another cybersecurity firm, recently reported a separate framework named OkoBot that also targets cryptocurrency investors. Kaspersky’s findings describe capabilities to harvest wallet files and browser data, capture credentials, inject malicious browser extensions and record wallet application windows.
The reports describe a pattern of threat actors using counterfeit software and specialized malware to directly access wallet files and browser-stored credentials.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








